SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-62147

MEDIUM · CVSS 6.5 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

The Tempo Operator's gateway component has a vulnerability that allows authenticated users to access span attributes from other tenants' namespaces due to inconsistent namespace-scoped redaction in query API responses when query RBAC is enabled. This could lead to unauthorized data exposure, potentially compromising tenant confidentiality. Organizations utilizing the Tempo Operator should prioritize addressing this vulnerability to safeguard their multi-tenant environments.

CVE
CVE-2026-62147
Severity
MEDIUM
CVSS
6.5
EPSS
0.21%

Original NVD Description

The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API response paths when query RBAC was enabled, allowing an authenticated user to read span attributes belonging to other tenants' namespaces.